1. Introduction
Global eServe Technologies LLP ("Company") respects your privacy. This Privacy Policy explains how we collect, use, store, share and protect personal information when you use SwifTrail. It is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules thereunder, as applicable.
2. Information we collect
(a) Merchant/Partner information: legal name, business address, PAN, GSTIN, CIN/LLPIN, bank account details, authorised signatory details, KYC documents, directors/partners' identity documents, contact details, login credentials. (b) End User information (processed on behalf of Merchants): name, email, phone, billing/shipping address, payment instrument details (card number handled through PCI-DSS compliant systems and tokenised as per RBI norms; we do not store full card numbers or CVV), UPI ID, bank account details for refunds/payouts, transaction details, device and IP data. (c) Agent/Retailer information: KYC (PAN, Aadhaar with consent, bank proof, photograph, address proof), biometric data transmitted for AEPS transactions (not stored by us beyond regulatory requirement), location data during transactions. (d) Technical data: IP address, device identifiers, browser type, log data, cookies (see Cookie Policy). (e) Communications: support tickets, emails, call recordings (with notice).
3. How we use information
To provide and operate payment, payout, escrow, verification, fintech and cross-border services; to perform KYC, AML and fraud checks as required by law and Payment Partners; to route, process, settle and reconcile transactions; to comply with RBI, NPCI, card-network, FEMA and tax requirements; to provide support; to improve our services and security (including AI-based fraud and routing models); to send service communications and, with consent, marketing communications.
4. Legal basis & consent
We process personal data on the basis of consent, performance of a contract, compliance with legal obligations and legitimate uses permitted under the DPDP Act. Aadhaar-based verification is performed only with the individual's explicit consent, via authorised channels, and in accordance with UIDAI regulations.
5. Sharing
We share data only: with Payment Partners as necessary to process transactions and comply with their requirements; with regulators, law enforcement and courts when legally required; with service providers (cloud hosting, KYC vendors, communication providers) bound by confidentiality; with Merchants (their End Users' transaction data); in connection with a merger or restructuring with notice. We do not sell personal data.
6. Cross-border transfers
Transaction data for cross-border payments is shared with overseas Payment Partners and correspondent banks as required to complete the transaction and meet compliance obligations, subject to applicable law. Payment system data is stored in India as required by RBI.
7. Data retention
We retain personal data for as long as necessary for the purposes above and for the periods required by law: transaction and KYC records — a minimum of five (5) years from the end of the business relationship or transaction date (or longer if required by RBI, PMLA or tax law); account and log data — as required for audit and security; marketing data — until consent is withdrawn.
8. Security
PCI-DSS compliant infrastructure, encryption in transit (TLS 1.2+) and at rest (AES-256), tokenisation, access controls, 2FA, monitoring, periodic VAPT by CERT-In empanelled auditors and an ISO 27001-aligned information security management system.
9. Your rights
Subject to law you may access, correct, update or request erasure of your personal data, withdraw consent, nominate a representative, and raise grievances. Requests: privacy@swiftrail.ai. We respond within the timelines prescribed under the DPDP Act.
10. Cookies
See Cookie Policy.
11. Children
The Platform is not intended for persons under 18.
12. Changes
We may update this policy; material changes will be notified on the Platform.
13. Grievance Officer / Data Protection Officer
to be published, to be published, Global eServe Technologies LLP, Flat No. 201, 2nd Floor, Plot 577, Triveni Apartment, N M Joshi Marg, Byculla (West), Mumbai – 400027, Maharashtra, India, privacy@swiftrail.ai, to be published.
Definitions used across our policies
Common definitions used across policies:
- "Company", "we", "us", "our" — Global eServe Technologies LLP, a limited liability partnership incorporated under the Limited Liability Partnership Act, 2008 (LLPIN to be published), having its registered office at Flat No. 201, 2nd Floor, Plot 577, Triveni Apartment, N M Joshi Marg, Byculla (West), Mumbai – 400027, Maharashtra, India, operating the brand and platform SwifTrail.
- "Platform" — the websites swiftrail.ai and swiftrail.in, dashboards, portals, mobile applications, APIs and related services.
- "Merchant" / "Partner" / "Agent" — a business or individual who has entered into an agreement with the Company to use the Platform.
- "End User" — a customer of a Merchant who makes a payment through the Platform.
- "Payment Partners" — RBI-licensed Payment Aggregators, banks (including escrow, sponsor and card-issuing banks), NBFCs, IRDAI-registered insurers, authorised government-scheme channels, card networks, NPCI and other regulated entities through which payment and financial services are facilitated.
